home/dictionary/significant security risk

significant security risk

nounverified·updated Sep 1, 2026

A risk-level characterization applied in security, privacy, and compliance contexts to a threat source, vulnerability, configuration, or actor whose assessed likelihood and potential impact together exceed an organization's or regulator's stated risk tolerance threshold — placing it in a priority tier that mandates active mitigation, escalation, or control action rather than acceptance or deferral. The concept underpins risk prioritization: quantifying or qualifying which risks must be addressed first, ensuring resources focus on the most consequential exposures. Frameworks including NIST RMF, FISMA, and CISA operational directives use the phrase descriptively — for example, CISA's Binding Operational Directive BOD 22-01 is titled "Reducing the Significant Risk of Known Exploited Vulnerabilities," treating it as a threshold marker, not a defined term — and the same pattern appears across HIPAA, ISO 27001, and CIS guidance, where "significant" functions as a calibrated severity qualifier aligned to each framework's impact and likelihood scales.

Framework senses

NIST SP 800-171r31 senseview framework →
§1 · attested_usage_reviewer_confirmed
No definition is given in NIST SP 800-171r3. The term is attested in use at 1 citation in that document; a definition is pending curation.
Increment 2: attested in 800-171r3 without a glossary definition.
Legacy lexicon import1 senseview framework →
§1 · web_lookup_draft
A risk-level characterization applied in security, privacy, and compliance contexts to a threat source, vulnerability, configuration, or actor whose assessed likelihood and potential impact together exceed an organization's or regulator's stated risk tolerance threshold — placing it in a priority tier that mandates active mitigation, escalation, or control action rather than acceptance or deferral. The concept underpins risk prioritization: quantifying or qualifying which risks must be addressed first, ensuring resources focus on the most consequential exposures. Frameworks including NIST RMF, FISMA, and CISA operational directives use the phrase descriptively — for example, CISA's Binding Operational Directive BOD 22-01 is titled "Reducing the Significant Risk of Known Exploited Vulnerabilities," treating it as a threshold marker, not a defined term — and the same pattern appears across HIPAA, ISO 27001, and CIS guidance, where "significant" functions as a calibrated severity qualifier aligned to each framework's impact and likelihood scales.
DR-088 backfill from the noun definition column